Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=duhoc123.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://duhoc123.com/ | 200 OK Content-Length: 119486 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.studentsingapore.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name="keywords" content="Du ...[3976 bytes skipped]... | ||
http://duhoc123.com/media/system/js/caption.js | 200 OK Content-Length: 2150 Content-Type: application/javascript | clean |
http://duhoc123.com/modules/mod_news_show_gk3/scripts/engine_1_11_compressed.js | 200 OK Content-Length: 1560 Content-Type: application/javascript | clean |
http://duhoc123.com/plugins/system/plg_jausersetting/script.js | 200 OK Content-Length: 5454 Content-Type: application/javascript | clean |
http://duhoc123.com/plugins/content/ja_tabs/ja_tabs.js | 200 OK Content-Length: 13732 Content-Type: application/javascript | clean |
http://duhoc123.com/templates/ja_teline_iii/js/ja.script.js | 200 OK Content-Length: 6674 Content-Type: application/javascript | clean |
http://duhoc123.com/templates/ja_teline_iii/js/ja.ddmod.js | 200 OK Content-Length: 15675 Content-Type: application/javascript | clean |
http://duhoc123.com/templates/ja_teline_iii/js/menu/css.js | 200 OK Content-Length: 1522 Content-Type: application/javascript | clean |
http://duhoc123.com/index.php | 200 OK Content-Length: 128481 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.studentsingapore.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/index.php" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name="keywords" co ...[4063 bytes skipped]... | ||
http://duhoc123.com/philippines.html | 200 OK Content-Length: 37992 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.nhatban24h.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/philippines.html" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name="ke ...[4151 bytes skipped]... | ||
http://duhoc123.com/philippines/du-hoc-phillipines.html | 200 OK Content-Length: 38200 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.nhatban24h.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/philippines/du-hoc-phillipines.html" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> ...[4151 bytes skipped]... | ||
http://duhoc123.com/du-hoc-my.html | 200 OK Content-Length: 89096 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.nhatban24h.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/du-hoc-my.html" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta name="keyw ...[4138 bytes skipped]... | ||
http://duhoc123.com/du-hoc-my/du-hoc-my.html | 200 OK Content-Length: 62110 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.nhatban24h.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/du-hoc-my/du-hoc-my.html" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta ...[4141 bytes skipped]... | ||
http://duhoc123.com/du-hoc-my/giao-dc-m.html | 200 OK Content-Length: 49870 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.nhatban24h.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/du-hoc-my/giao-dc-m.html" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta ...[4114 bytes skipped]... | ||
http://duhoc123.com/du-hoc-my/visa-du-hc.html | 200 OK Content-Length: 48831 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.nhatban24h.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-gb" lang="en-gb"> <head> <base href="http://duhoc123.com/du-hoc-my/visa-du-hc.html" /> <meta http-equiv="content-type" content="text/html; charset=utf-8" /> <meta name="robots" content="index, follow" /> <meta ...[4157 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: duhoc123.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 30 Jan 2015 11:55:13 GMT
Pragma: no-cache
Server: Apache
Vary: User-Agent,Accept
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Fri, 30 Jan 2015 11:55:14 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: c94b313208fdec6294bc7c6db925e016=rYgt3pU9YyOh_f_egmmfu37_vbhhrXlKCYdvq9ymkC4Rc9mMdpUutj_zBTB_qeCG; path=/
Set-Cookie: ja_teline_iii_tpl=t7zGfttQ6GSDMpI-WC42xFWtLvOXOjY5ECixcS-RZD4.; expires=Wed, 20-Jan-2016 11:55:13 GMT; path=/
X-Died: timeout at scan.pm line 1566.
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: duhoc123.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 30 Jan 2015 11:55:13 GMT
Pragma: no-cache
Server: Apache
Vary: User-Agent,Accept
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Fri, 30 Jan 2015 11:55:14 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: c94b313208fdec6294bc7c6db925e016=rYgt3pU9YyOh_f_egmmfu37_vbhhrXlKCYdvq9ymkC4Rc9mMdpUutj_zBTB_qeCG; path=/
Set-Cookie: ja_teline_iii_tpl=t7zGfttQ6GSDMpI-WC42xFWtLvOXOjY5ECixcS-RZD4.; expires=Wed, 20-Jan-2016 11:55:13 GMT; path=/
X-Died: timeout at scan.pm line 1566.
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: duhoc123.com
Referer: http://www.google.com/search?q=duhoc123.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: duhoc123.com
Referer: http://www.google.com/search?q=duhoc123.com
Result:
The result is similar to the first query. There are no suspicious redirects found.